1.

Solve : Virus Alert in Toolbar. Already got Combofix logs.?

Answer»

Hi there, I was able to get to this point from reading other peoples posts. This site is a real helper! I am so greatfull at how great you guys are! WOW.

anyways, here is my Combofix log and Hijackthis logs



[recovering disk space -- attachment deleted by admin]Is there an icon in your toolbar, a yellow triangle warning sign WELCOME to CH.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
- O16 - DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC} -
- O21 - SSODL: mgxfebsq - {7F2CD258-C7A5-421C-B7E4-50D8623A2B55} - C:\WINDOWS\mgxfebsq.dll


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

Folder::
C:\x

File::
C:\WINDOWS\system32\2.ico
C:\WINDOWS\system32\casino3.ico
C:\WINDOWS\system32\casino2.ico
C:\WINDOWS\system32\casino1.ico
C:\WINDOWS\system32\1.ico
C:\WINDOWS\vmgspntbnrp.dll
C:\WINDOWS\dtseqrxk.dll
C:\WINDOWS\mgxfebsq.dll
C:\WINDOWS\fqbewlna.dll
C:\WINDOWS\mqgldfvo.exe

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7287293E-B0BE-4A31-B52B-EA15F57679E3}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

[-HKEY_CLASSES_ROOT\clsid\{94e952a4-fae1-40e5-bbe1-8199d8cf7fd0}]

[-HKEY_CLASSES_ROOT\fqbewlna.1]

[-HKEY_CLASSES_ROOT\TypeLib\{0955BCF0-2DB3-4926-B985-1ED8F0894D73}]

[-HKEY_CLASSES_ROOT\fqbewlna]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the SCREENSHOT below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeHere is the log but for some reason it didnt reboot before giving me this log?

[recovering disk space -- attachment deleted by admin]

    Download
OTMoveIt2 by OldTimer
  • Save it to your desktop.
Note: If you are running on Vista, right-click on OTMoveIt2.exe and choose Run As Administrator.

  • Double-click OTMoveIt2.exe to run it.
  • Copy the lines in the codebox below.
[/list]Code: [Select][kill explorer]
C:\WINDOWS\system32\2.ico
C:\WINDOWS\system32\casino3.ico
C:\WINDOWS\system32\casino2.ico
C:\WINDOWS\system32\casino1.ico
C:\x
C:\WINDOWS\system32\1.ico
C:\WINDOWS\vmgspntbnrp.dll
C:\WINDOWS\dtseqrxk.dll
C:\WINDOWS\mgxfebsq.dll
C:\WINDOWS\fqbewlna.dll
C:\WINDOWS\mqgldfvo.exe
HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7287293E-B0BE-4A31-B52B-EA15F57679E3}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{94E952A4-FAE1-40E5-BBE1-8199D8CF7FD0}
HKEY_CLASSES_ROOT\clsid\{94e952a4-fae1-40e5-bbe1-8199d8cf7fd0}
HKEY_CLASSES_ROOT\fqbewlna.1
HKEY_CLASSES_ROOT\TypeLib\{0955BCF0-2DB3-4926-B985-1ED8F0894D73}
HKEY_CLASSES_ROOT\fqbewlna
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\mgxfebsq
EmptyTemp
[start explorer]
  • Return to OTMoveIt2, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) and paste it in your next reply.
  • Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose YES. If not, reboot anyway.Here are my results.

[recovering disk space -- attachment deleted by admin]Download Malwarebytes' Anti-Malware (MBAM)

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    .
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    Here it is..

    [recovering disk space -- attachment deleted by admin]How is everything now?Malwarebytes' Anti-Malware 1.28
    Database version: 1147
    Windows 5.1.2600 Service Pack 2

    13/09/2008 10:44:33 PM
    mbam-log-2008-09-13 (22-44-33).txt

    Scan type: Full Scan (C:\|D:\|)
    Objects scanned: 192594
    Time elapsed: 46 minute(s), 28 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 52

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\0.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\1.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\2.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\3.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\4.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\5.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\Program Files\PCHealthCenter\7.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\emnf.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ccnrgh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\mmx98354.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\mx98354.dll.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ngysvesj.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\opnkjklm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ssqoommN.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\swuewl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvTMfCr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\vjtdfejx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\vtUlKBUO.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\wxwptowi.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\xxyYqnNh.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\YUR4E5.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\YUR4E6.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\YUR4E8.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\YUR4EB.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\Qoobox\Quarantine\C\WINDOWS\system32\YUR506.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP541\A0112820.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112868.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112869.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112871.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112873.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112874.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112875.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112876.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112885.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112886.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112887.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112888.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112889.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112890.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112891.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112892.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112893.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112895.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112897.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112898.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112899.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112900.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112902.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112903.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112904.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{97AF48F9-1888-4A08-B210-5534F302F4BA}\RP542\A0112901.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    C:\_OTMoveIt\MovedFiles\09132008_092408\x (Trojan.FakeAlert) -> Quarantined and deleted successfully.
    How does that look?Delete the copy of ComboFix you have now and use the new version.

    Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

    Link #1
    Link #2

    **Note: It is important that it is saved directly to your Desktop

    Close any open Web browsers. (FIREFOX, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Double click combofix.exe & follow the prompts.
    When finished ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.


    Discussion

    No Comment Found